cbcvebase.
CVE-2017-7657
published 2018-06-26

CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled)…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
16.15%
96.6th percentile
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianjetty9< jetty9 9.2.25-1 (bookworm)jetty9 9.2.25-1 (bookworm)
eclipsejetty<= 9.2.26
eclipsejetty>= 9.3.0 < 9.3.249.3.24
eclipsejetty>= 9.4.0 < 9.4.119.4.11
hpxp_p9000_command_view>= 8.4.0-00 < 8.6.2-008.6.2-00
netappe-series_santricity_os_controller11.0 – 11.50.1
netapponcommand_system_manager
netapponcommand_unified_manager< 5.2.45.2.4
netappsnap_creator_framework< 4.3.34.3.3
netappsnapcenter< 4.1p34.1p3
netappsnapmanager< 3.4.23.4.2
oraclerest_data_services
oraclerest_data_services
oraclerest_data_services
oraclerest_data_services
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
the_eclipse_foundationeclipse_jetty>= 9.3.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= 9.4.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= unspecified < 9.3.249.3.24
the_eclipse_foundationeclipse_jetty>= unspecified < 9.4.119.4.11
the_eclipse_foundationeclipse_jettyunspecified – 9.2.0

Detection & IOCsextracted from sources · hover to see the quote

  • Detect HTTP request smuggling via chunked transfer-encoding integer overflow: monitor for abnormally large chunk sizes in Transfer-Encoding: chunked requests that may be interpreted as pipelined requests by Jetty backends
  • Flag HTTP requests with oversized Transfer-Encoding chunk lengths traversing intermediary proxies/load balancers destined for Jetty backends, as these may be used to smuggle unauthorized pipelined requests past authorization controls
  • ·CVE-2017-7657 affects Jetty 9.2.x and older (all configurations), 9.3.x (all configurations), and 9.4.x ONLY when RFC2616 compliance mode is explicitly enabled (non-default). Jetty 9.4.x in default configuration is NOT vulnerable.
  • ·Exploitation requires the Jetty instance to be deployed behind an intermediary (e.g., reverse proxy, WAF) that passes arbitrarily large chunk sizes through unchanged; direct exposure without such an intermediary significantly reduces exploitability.
  • ·Red Hat rates this as Low severity for Jetty embedded in the nutch package (Red Hat Satellite 5) because the nutch service is not exposed, making exploitation difficult.
  • ·Data Grid 8 is confirmed not affected. Data Grid 7 deprecated the agent-bond utility that exposes this flaw; it is disabled by default and no longer supported.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.